top of page

SEARCH

Find what you need

246 results found for "Audit"

  • For Compliance to Change It Must Raise Its Standard

    Organizations declare their compliance by attestation, verified by internal audits, and confirmed by external audits. operational approach is hard to find when you believe you are already “In Compliance”, confirmed by audits

  • Integrative Compliance: Embedding Regulatory Obligations in Operational Capability

    probably noticed something frustrating: organizations can have excellent compliance documentation, pass audits It's the difference between having environmental procedures that get referenced during audits versus environmental activities: quarterly emissions monitoring, annual environmental training, periodic waste audits compliance status through both automated monitoring and human verification without waiting for the next audit The Bottom Line The future of compliance isn't better documentation or more audits—it's integrative compliance

  • One Day or Day 1

    themselves trapped by a siloed, reactive, and divided practice reinforced by years of prescriptive rules and audits We’re too busy putting in controls, auditing, and working on corrective actions to be proactive.

  • What Is Your MOC Maturity Index?

    This may be enough to pass an audit but is not enough to effectively manage the risks due to: asset,

  • Why GRC Should be GRE

    an old model where meeting obligations (the act of compliance) is a checkbox activity reinforced by audits

  • Tyrannical Compliance

    This isn't hard to imagine when excessive audits and controls are put in place as a reaction to a serious incident or serious audit findings. This produces better results than inspecting and auditing for conformance afterwards. The lack of prescription, while a good thing, is viewed negatively because it's more difficult to audit As a consequence, auditors can no longer tell organizations what to do and neither should they.

  • Does Compliance Need an Incident Management System?

    Use of Audits The use of periodic audits as the primary compliance control is all too common and has By design audits provide evidence of what has happened. Audits work best when organizations are mostly “in-compliance.” Audits cannot correct what has already happened. Are audits enough to provide the assurance that stakeholders require?

  • Compliance – The Road Less Traveled

    The path of " necessary evil " is fraught with uncertainty and is driven by inspections and audits. Even with the multitude of action items that come from these audits, you cannot "react" your way to better can take the road less traveled, and be in the company of those that want more than just to pass an audit

  • OOPS, we put the obligations in the wrong place.

    The audit gets passed. call this negligence: managers handing their responsibilities off to consultants, departments, and auditors — a system that does what the obligation requires, under real conditions, whether or not anyone is auditing "The system didn't flag it" becomes the new "the auditor didn't catch it" — one more place to send accountability Today we manage the compliance function — the program, the reporting, the audit calendar.

  • Proactive GRC

    appropriate risk, and legal and regulatory requirements are properly met as evidenced primarily through audits Fundamentally, GRC started as a way to: Avoid Prosecution, Prevent Loss, and Audit and Control The primary emphasis from a systems and process perspective has been on the audit function to verify The focus on audits parallels similar approaches applied to quality, safety and environmental programs This audit-based approach will exact a heavy burden on organizations.

  • Compliance 1 and 2

    The internal audit function still has a role under Compliance 2. However, auditing now focuses on evaluating effectiveness as measured against compliance outcomes.

  • Closing the Compliance Effectiveness Gap

    Step   The first step toward closing The Compliance Effectiveness Gap  is a:   TOTAL VALUE COMPLIANCE AUDIT This is not a traditional audit.  

bottom of page